top of page

AI Governance for Law Firms Shifts from Policy to Enforcement

3 hours ago
5 min read
AI Governance for Law Firms Shifts from Policy to Enforcement

AI governance for law firms and insurers is moving from written policy to enforcement at the point of action, and a distinct vendor category is forming around it. Jalubro, a London legal-technology consultancy founded in 2015, has rebranded its J-10 control layer as Ephiria and extended it to govern not only how staff use AI and how autonomous agents behave, but the automated back-office processes that move client data between enterprise systems without human review. The pitch is aimed squarely at regulated firms now being asked, by regulators, clients and insurers alike, to prove what their controls did rather than confirm that a policy exists on paper.


What has actually changed?


Less than the launch language suggests, and that is the first thing worth noting. Ephiria is not a new product. It is the same platform Jalubro brought to market as J-10 in June 2026, now consolidated under a single brand roughly three months later. The substantive addition is the third surface Ephiria says it governs: automated system-to-system processes, alongside the two surfaces J-10 already addressed, people using AI tools and AI agents taking actions.


The mechanism the company describes is consistent across both versions. Ephiria sits above an organisation's existing stack and intercepts an action before it completes, then permits it, blocks it, or routes it for human approval, resolving internal policy, regulatory obligations, client outside counsel guidelines and the firm's own delegation of authority in a fixed order. Each decision is written to a tamper-evident record. For a solicitor pasting a draft agreement into a general AI assistant, that means client identifiers and privileged content are stripped before the model sees them and reinstated in the response, with a log of what was redacted and on whose authority. For an agent attempting to authorise a claim payment above its granted limit, it means the action is held and referred to a human rather than executed.


Why are regulators and insurers raising the bar now?


The timing tracks a sharp move in UK legal regulation. On 17 August 2026 the Solicitors Regulation Authority published a warning notice on the misuse of AI, flagging two concerns: false or incorrect information reaching the courts through AI misuse, including hallucinated citations, and confidential client information entered into AI tools that lack appropriate safeguards. The regulator disclosed that it had received 42 reports of potential AI misuse between July 2025 and July 2026, with several investigations under way covering inaccurate citations, supervision failures and confidentiality breaches. The notice states that firms failing to have proper regard to it risk disciplinary action.


The financial exposure sits in Brussels as well as London, though the detail matters more than the press framing around it usually allows. Under the EU AI Act, breaches of most operator obligations, including those for general-purpose AI models, can attract fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher, with a separate band of up to 7.5 million euros or 1% for supplying incorrect, incomplete or misleading information to authorities. Prohibited practices sit at the top of the scale, at 35 million euros or 7%. What became enforceable on 2 August 2026 were the Article 50 transparency duties and the Commission's power to fine GPAI model providers. The high-risk requirements were not switched on at that point: the Digital Omnibus package, now Regulation (EU) 2026/1744, deferred them to December 2027 and August 2028. Firms weighing governance spend should plan against those later dates for the high-risk tier, not an August 2026 deadline that did not land.


There is a third source of pressure that does not wait for any statutory timetable. Outside counsel guidelines increasingly carry AI conditions, and whatever a firm states about its AI controls on an insurance proposal form is a representation it may later have to evidence. None of the three parties, regulator, client or insurer, is asking whether a firm has a policy. All three are asking what its controls actually did, and that is a question a document cannot answer after the fact.


What does Ephiria claim sets it apart?


Jalubro's founder and chief executive Arran Braganza frames the gap as one the legal

sector has largely ignored: while the profession debated whether people should use AI at all, the automated processes already moving client data across enterprise systems ran unsupervised for years and were never asked to evidence what they did. Ephiria, on the company's account, governs the action regardless of whether a person, an agent or an automated workflow is taking it.


That third surface, automated processes, is where the company stakes its distinction from rival tools. Many vendors now govern AI agents; far fewer, it argues, govern the system-to-system automations that have run inside enterprises for years and are, on Jalubro's reading, where genuine authority breaches occur. The company says Ephiria is deployed across Europe, the Middle East, Asia and the United States, drawing on a decade of work inside regulated environments, though it has not named the client organisations involved.


Is enforcement a new category, or is the market already moving there?


The broader claim, that governance must enforce at the point of execution rather than monitor after it, is less a Jalubro insight than the direction the whole category is travelling. Holistic AI, one of the more established governance platforms, markets Guardian Agents that it says monitor continuously and intervene in real time. Microsoft released an open-source Agent Governance Toolkit in April 2026 built around deterministic policy-enforcement controls. Independent market analysis has identified runtime enforcement, paired with pre-deployment assessment and traceable records, as the axis on which governance products are increasingly competing.


The market backdrop explains the rush. The agentic AI market was valued at roughly 19.3 billion dollars in 2026 and is projected by MarketsandMarkets to reach 205.9 billion dollars by 2033, a compound annual growth rate above 40%. The AI governance software market that sits alongside it is far smaller, measured in hundreds of millions of dollars for 2026 across the main research estimates, and notably fragmented, with no single vendor dominating across traditional machine learning, generative AI and agentic systems. That fragmentation is the opening every entrant is chasing.


For buyers, the practical takeaway is to separate the durable claim from the positioning. Enforcement at execution and audit-ready evidence are becoming table stakes across the category, not a single-vendor advantage. Ephiria's more specific and more testable proposition is that it extends the same control to unattended automated processes, the layer most governance tools still leave alone. Whether that distinction holds up against competitors moving in the same direction is the question a procurement team should put to any shortlist.


Why This Matters to FinanceX Readers


Every regulated firm, in law and in financial services, is converging on the same operating reality: staff, agents and background automations will act on confidential data whether or not a policy governs them, so the meaningful choice is between governed execution and unmonitored exposure. The evidential burden is shifting from having controls to proving what they did, and it cannot be met retrospectively.


For investors and operators, the signal is that AI governance is hardening into its own budget line and its own vendor category, distinct from general enterprise security. The competitive question is narrowing fast, from whether AI activity should be captured to which product enforces policy at the moment of action and produces a record a regulator or insurer will accept. Watching where enforcement-layer spending concentrates, and which claims survive contact with procurement, will indicate where compliance-technology budgets flow next.

 
 
bottom of page